Hash pin Github workflows #198
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
#197
Changes
Hash pin GitHub Owned Workflows: although they are more trustful than the overall github actions it is important to notice that they are still open source projects.
Let me know what you think.
PS: this is just an extra precaution, the workflow is already safe enough following minimal permissions on workflow. The hash pin will only ensure that no "malicious" version will be running instead of the original and trustful one.